Open Source Vulnerabilities
Kernel
i40e: Fix kernel crash during module removal
Kernel
ipv6: sr: fix out-of-bounds read when setting HMAC data.
Kernel
ipv6: sr: fix out-of-bounds read when setting HMAC data.
Kernel
nvme-tcp: fix UAF when detecting digest errors
Kernel
IB/core: Fix a nested dead lock as part of ODP flow
Kernel
erofs: fix pcluster use-after-free on UP platforms
Kernel
RDMA/irdma: Report the correct max cqes from query device
Kernel
RDMA/irdma: Report the correct max cqes from query device
Kernel
net/smc: Fix possible access to freed memory in link clear
Kernel
net/smc: Fix possible access to freed memory in link clear
Kernel
swiotlb: avoid potential left shift overflow
Kernel
s390/boot: fix absolute zero lowcore corruption on boot
Kernel
s390/boot: fix absolute zero lowcore corruption on boot
Kernel
of: fdt: fix off-by-one error in unflatten_dt_nodes()
Kernel
of: fdt: fix off-by-one error in unflatten_dt_nodes()
Kernel
cgroup: Add missing cpus_read_lock() to cgroup_attach_task_all()
Kernel
cgroup: Add missing cpus_read_lock() to cgroup_attach_task_all()
Kernel
peci: cpu: Fix use-after-free in adev_release()
Kernel
ieee802154: cc2520: add rc code in cc2520_tx()
jackson-databind, jackson-databind, jackson-databind
jackson-databind, jackson-databind, jackson-databind
jackson-databind, jackson-databind, jackson-databind, jackson-databind, jackson-databind, jackson-databind
jackson-databind/ jackson-databind/ jackson-databind/ jackson-databind/ jackson-databind/ jackson-databind
jackson-databind, jackson-databind, jackson-databind, jackson-databind
jackson-databind/ jackson-databind/ jackson-databind/ jackson-databind
expat
Updated expat packages fix security vulnerability
firejail
Updated firejail packages fix security vulnerability
perl-HTTP-Daemon
Updated perl-HTTP-Daemon packages fix security vulnerability
perl-HTTP-Daemon
Updated perl-HTTP-Daemon packages fix security vulnerability
python-mako
Updated python-mako packages fix security vulnerability
python-mako
Updated python-mako packages fix security vulnerability
squid
Updated squid packages fix security vulnerability
libjpeg
Updated libjpeg packages fix security vulnerability
nodejs
Updated nodejs packages fix security vulnerability
thunderbird, thunderbird-l10n
Updated thunderbird packages fix security vulnerability
thunderbird/ thunderbird-l10n
Updated thunderbird packages fix security vulnerability
github.com/cloudflare/goflow/v3
Cloudflare GoFlow vulnerable to a Denial of Service in the sflow packet handling package
github.com/cloudflare/goflow/v3
Cloudflare GoFlow vulnerable to a Denial of Service in the sflow packet handling package
parity-wasm
Crate `parity-wasm` deprecated by the author
expat, expat, expat
Security update for expat
webkit2gtk3-soup2, webkit2gtk3, webkit2gtk4, webkit2gtk3, webkit2gtk3-soup2, webkit2gtk4
Security update for webkit2gtk3
webkit2gtk3-soup2/ webkit2gtk3/ webkit2gtk4/ webkit2gtk3/ webkit2gtk3-soup2/ webkit2gtk4
Security update for webkit2gtk3
ImageMagick, ImageMagick, ImageMagick
Security update for ImageMagick
ImageMagick/ ImageMagick/ ImageMagick
Security update for ImageMagick
cosign, cosign
Security update for cosign
python39, python39-core, python39-core, python39, python39-core, python39-documentation, python39, python39-core, python39-documentation
Security update for python39
python39/ python39-core/ python39-core/ python39/ python39-core/ python39-documentation/ python39/ python39-core/ python39-documentation
Security update for python39
hunspell
Heap-buffer-overflow in AffixMgr::cpdcase_check
DotNetNuke.Core, DotNetNuke.Web
DNN vulnerable to Relative Path Traversal
DotNetNuke.Core/ DotNetNuke.Web
DNN vulnerable to Relative Path Traversal
react-native-reanimated
react-native-reanimated vulnerable to ReDoS
react-native-reanimated
react-native-reanimated vulnerable to ReDoS
css-what
css-what vulnerable to ReDoS due to use of insecure regular expression
css-what
css-what vulnerable to ReDoS due to use of insecure regular expression
rdiffweb
rdiffweb's lack of token name length limit can result in DoS or memory corruption
rdiffweb
rdiffweb's lack of token name length limit can result in DoS or memory corruption
moodle/moodle, moodle/moodle, moodle/moodle
Moodle remote code execution
moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle remote code execution
moodle/moodle, moodle/moodle, moodle/moodle
Moodle No groups filtering in H5P activity attempts report
moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle No groups filtering in H5P activity attempts report
moodle/moodle, moodle/moodle, moodle/moodle
Moodle Stored Cross-site Scripting and page denial of service
moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle Stored Cross-site Scripting and page denial of service
joplin
Joplin Remote Code Execution
moodle/moodle, moodle/moodle, moodle/moodle
Moodle Minor SQL injection risk in admin user browsing
moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle Minor SQL injection risk in admin user browsing
lief
LIEF vulnerable to denial of service through segmentation fault
lief
LIEF vulnerable to denial of service through segmentation fault
